Commit fb2466a6 by mmorenog

Update APT_HackingTeam.yar

parent 9623f36f
...@@ -8,7 +8,6 @@ rule bin_ndisk { ...@@ -8,7 +8,6 @@ rule bin_ndisk {
author = "Florian Roth" author = "Florian Roth"
reference = "https://www.virustotal.com/en/file/a03a6ed90b89945a992a8c69f716ec3c743fa1d958426f4c50378cca5bef0a01/analysis/1436184181/" reference = "https://www.virustotal.com/en/file/a03a6ed90b89945a992a8c69f716ec3c743fa1d958426f4c50378cca5bef0a01/analysis/1436184181/"
date = "2015-07-07" date = "2015-07-07"
score = 100
hash = "cf5089752ba51ae827971272a5b761a4ab0acd84" hash = "cf5089752ba51ae827971272a5b761a4ab0acd84"
strings: strings:
$s1 = "\\Registry\\Machine\\System\\ControlSet00%d\\services\\ndisk.sys" fullword wide $s1 = "\\Registry\\Machine\\System\\ControlSet00%d\\services\\ndisk.sys" fullword wide
...@@ -29,7 +28,6 @@ rule Hackingteam_Elevator_DLL { ...@@ -29,7 +28,6 @@ rule Hackingteam_Elevator_DLL {
author = "Florian Roth" author = "Florian Roth"
reference = "http://t.co/EG0qtVcKLh" reference = "http://t.co/EG0qtVcKLh"
date = "2015-07-07" date = "2015-07-07"
score = 70
hash = "b7ec5d36ca702cc9690ac7279fd4fea28d8bd060" hash = "b7ec5d36ca702cc9690ac7279fd4fea28d8bd060"
strings: strings:
$s1 = "\\sysnative\\CI.dll" fullword ascii $s1 = "\\sysnative\\CI.dll" fullword ascii
...@@ -52,7 +50,6 @@ rule HackingTeam_Elevator_EXE { ...@@ -52,7 +50,6 @@ rule HackingTeam_Elevator_EXE {
author = "Florian Roth" author = "Florian Roth"
reference = "Hacking Team Disclosure elevator.c" reference = "Hacking Team Disclosure elevator.c"
date = "2015-07-07" date = "2015-07-07"
score = 70
hash1 = "40a10420b9d49f87527bc0396b19ec29e55e9109e80b52456891243791671c1c" hash1 = "40a10420b9d49f87527bc0396b19ec29e55e9109e80b52456891243791671c1c"
hash2 = "92aec56a859679917dffa44bd4ffeb5a8b2ee2894c689abbbcbe07842ec56b8d" hash2 = "92aec56a859679917dffa44bd4ffeb5a8b2ee2894c689abbbcbe07842ec56b8d"
hash = "9261693b67b6e379ad0e57598602712b8508998c0cb012ca23139212ae0009a1" hash = "9261693b67b6e379ad0e57598602712b8508998c0cb012ca23139212ae0009a1"
...@@ -73,6 +70,3 @@ rule HackingTeam_Elevator_EXE { ...@@ -73,6 +70,3 @@ rule HackingTeam_Elevator_EXE {
condition: condition:
uint16(0) == 0x5a4d and filesize < 3000KB and all of ($x*) and 3 of ($s*) uint16(0) == 0x5a4d and filesize < 3000KB and all of ($x*) and 3 of ($s*)
} }
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment